Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes
1–10 of 76 posts
Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes
#2It is better for open source projects to just pass a license claiming, software is not available for free in EU and to make EU companies pay sky high fees to use the software that is freely available for everyone else.
That way EU bureaucrats will stop trying to be the World Police without paying the price that USA has to pay to keep its global influence (like funding military of other nations while americans die in hospitals, in homelessness , intentionally making american exports disadvantageous just to keep its global reserve currency status, etc).
It is absolutely insane to me how EU thinks it can decide what charging port everyone should use USB-C , cookie banners for everyone, GDPR nightmare for everyone, and now this new government rule on opensource contributors to software being held liable for security breaches.
Absolutely crazy. They just want free lunch while trying to control everyone and everything.
Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes
#3This just further incentivises over-regulatory EU to keep making burdensome regulation that slows down innovation for everyone. It is better for open source projects to just pass a license claiming, software is not available for free in EU and to make EU companies pay sky high fees to use the software that is freely available for everyone else. That way EU bureaucrats will stop trying to be the World Police without p…
Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes
#4This just further incentivises over-regulatory EU to keep making burdensome regulation that slows down innovation for everyone. It is better for open source projects to just pass a license claiming, software is not available for free in EU and to make EU companies pay sky high fees to use the software that is freely available for everyone else. That way EU bureaucrats will stop trying to be the World Police without p…
I won't bother addressing most of the nonsense you've written. I'll just say that the US has FedRAMP ( https://en.wikipedia.org/wiki/FedRAMP ) and EO 14028 ( https://www.federalregister.gov/documents/2021/05/17/2021-10... ). So if you imagine that this is somehow an EU-specific thing and doesn't affect the US, you're very wrong. Not to mention NIST and FIPS and CISA.
All major governments have policies like this, its an issue when government tries to over regulate private matters.
What government regulates inside its own workforce, is absolutely upto them. But government shouldnt interfere so much into private matters.
Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes
#5This just further incentivises over-regulatory EU to keep making burdensome regulation that slows down innovation for everyone. It is better for open source projects to just pass a license claiming, software is not available for free in EU and to make EU companies pay sky high fees to use the software that is freely available for everyone else. That way EU bureaucrats will stop trying to be the World Police without p…
"cookie banners for everyone" -> cookie banners only if your website is using cookies in a way that needs a cookie banner. There are plenty of sites or web analytics technologies that don't mandate the use of a cookie banner.
"GDPR nightmare for everyone" -> only for companies that intend touse personal data in non-ethical ways (cf. for instance: https://www.iccl.ie/digital-data/europes-hidden-security-cri... ).
"now this new government rule on opensource contributors to software being held liable for security breaches." -> Indeed, that's problematic, specially the way this was (not) discussed with the open source sector. Cf. https://cnll.fr/news/la-france-doit-prot%C3%A9ger-sa-fili%C3... and https://cnll.fr/news/declaration-cra-cyber-resilience-act/ (two texts that I wrote, in French, last year).
Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes
#6Otherwise all the SV dudes complaining about the over burocratics: How to improve Software security? Only alternative I can think of, is the goverment pays for the security. For me thats a worser solution.
Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes
#7This just further incentivises over-regulatory EU to keep making burdensome regulation that slows down innovation for everyone. It is better for open source projects to just pass a license claiming, software is not available for free in EU and to make EU companies pay sky high fees to use the software that is freely available for everyone else. That way EU bureaucrats will stop trying to be the World Police without p…
"USB-C" -> Good for consumer, I believe. "cookie banners for everyone" -> cookie banners only if your website is using cookies in a way that needs a cookie banner. There are plenty of sites or web analytics technologies that don't mandate the use of a cookie banner. "GDPR nightmare for everyone" -> only for companies that intend touse personal data in non-ethical ways (cf. for instance: https://www.iccl.ie/digital-da…
With the same logic EU had tried to make Micro USB mandatory for everyone, it was a very poorly executed charging port which would break often and easily.
If it was made industry standard back then, USB-C would have probably never come along or would have taken much much longer.
The road to hell is paved with good intention, I doubt any decent government (which EU is) would pass laws that is bad for its people in short term.
It’s just that these burden some regulations backfire in the long term.
The problems with GDPR and Cookie Banner are well documented, it puts EU startups at a disadvantage because of having to pass all regulations before they can innovate and get up from the ground. Regulations like this should not apply to startups, the harm done to economy is far more than harm done to the public.
Or else , EU citizens will forever be left using American Software, driving Japanese cars (EU car makers are in decline), use Chinese and American Robots (Largest German Robot company (KUKA Robotics) sold to China), use Chinese Solar Panels, Korean Phones, etc.
I get what you’re saying, it all sounds sweet and good on paper.
But it ends up being a race where brilliant european minds are running with 20kg weights on their shoes, while other major nations are supplying stimulants for their innovators to win the gold medal.
It’s just the reality of what’s happening, if it continues EU will die a slow and painful death (Saying the truth as a well wisher for europe, they are pro-consumer in great many ways, but they are over regulating and hurting their next generation)
Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes
#8This just further incentivises over-regulatory EU to keep making burdensome regulation that slows down innovation for everyone. It is better for open source projects to just pass a license claiming, software is not available for free in EU and to make EU companies pay sky high fees to use the software that is freely available for everyone else. That way EU bureaucrats will stop trying to be the World Police without p…
[1] https://berthub.eu/articles/posts/eu-cra-what-does-it-mean-f...
Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes
#9That's the state of our industry today. In some ways, Open source seems among the better students of the class. In other ways, Open source is like a million people each contributing a few parts to a society critical factory, nobody noticing how big we grew. Of course that makes people uneasy.
I think something like this is unavoidable. How to get the max impact with minimal overhead is the most important discussion now, so I applaud apache's initiative.
Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes
#10> establishment of common specifications for secure software > development based on existing open source best practices.
The problem with "best practices" is that there are always better practices. Hopefully this group don't ossify around "best practices" that are already out of date but become research focused. To be blunt, a problem is not that "best practices" are never followed, but that we have about 30 years of technical security debt to catch up with.
This foundation is also going to be a money pit, because it needs to help other developers. It cannot rule, dictate or enforce anything. Since most European devs are going to want to join in, it's going to be paying out for conferences, education, development grants and T-shirts. It'll need a pipeline of money from EU and commerce - and there's the danger of corruption.